Conducting threat detection and response
In this section, we will review managed services that allow us to review logs to pinpoint and respond to actual threats. Threat detection and response (TDR) services are crucial in cloud environments because they provide real-time monitoring, rapid threat identification, and automated response capabilities to protect sensitive data and infrastructure from constantly evolving cyber threats. We will cover some of the most common recommendations for configuring Amazon GuardDuty, Microsoft Defender, and Google Security Command Center. This section does not replace the official documentation for using these services for threat management and response.
Amazon GuardDuty
Amazon GuardDuty is a threat detection and monitoring service that pulls data from various sources such as VPC Flow Logs, AWS CloudTrail, CloudTrail S3 data event logs, and DNS logs. It uses machine learning to review the logs and alerts us only on events that require further...